Skip to main content
Back to Home
1. Product2. Agents3. Governance4. CloudOps5. FinOps6. Security
AI + Data + Cloud · Pillar 4
☁️

CloudOps & Infrastructure

Technology

67AWS Accounts

67 AWS accounts discovered in 2.67 seconds. Terraform + CDK with 3-tier testing. Docker-first supply chain.

First org-wide inventory in <10 seconds via Config Aggregator
AI agents build governed & Humans ship trusted. 80% autonomy & 100% accountability.
Section Four (Ch.17-23)

Technology for Speed and Distributed Innovation

The objective for technology is to make it easy for your pods to constantly develop and release digital and AI innovations to customers and users. Seven broad capabilities are needed to build a technology environment that can support a digital transformation.

A more surgical and value-backed approach to cloud. The automation of software development and deployment is fundamental to building and releasing high-quality software. ADLC delivers this through Docker-first enforcement (nnthanh101/* only), Local-First Hybrid-Cloud (Docker/K3D -> AWS), and multi-account landing zones with READONLY-safe automation.

Source: Rewired: The McKinsey Guide to Outcompeting in the Age of Digital and AI (Lamarre, Smaje, Zemmel, 2023)

Platform Evolution

IaC generation improves with each Claude release — more accurate Terraform modules, better CDK constructs. NemoClaw adds kernel-level security validation for agent-generated infrastructure.

Component Map

12 components implementing this pillar

TypeNameWhyBusiness Value
Agentinfrastructure-engineer (sonnet)CDK + Terraform IaC for multi-account AWS landing zonesGitOps reproducibility — every resource declaratively defined
Agentkubernetes-engineer (sonnet)K3s + ArgoCD + Helm for containerised workloadsPlatform engineering that scales from laptop to prod
Command/terraform:test3-tier testing: functional, integration, E2ESecurity issues caught before terraform plan
Command/terraform:costInfracost pre-deploy cost estimation with FOCUS complianceFinOps integrated into IaC review — no surprise bills
Command/cdk:synthCDK synthesis with cdk-nag security checksAPRA CPS 234 alignment verified at synth time
Command/devcontainer:validate-registryScan all FROM and image: references for registry complianceSupply chain integrity — blocked registries caught in PR
Command/kubernetes:deployArgoCD application sync with health checksZero-downtime deployments with automated rollback
Command/inventory:lz-cross-validateREADONLY multi-account inventory cross-validationConfig Aggregator org-wide — 67 accounts in <10 seconds
Skillaws-health-event-triageEC2 health event investigation workflowREBOOT_FIRST_DECOMMISSION_SECOND anti-pattern eliminated
Skillterraform/deploy-lifecycleTerraform module publish and deploy lifecycle patternsRegistry-to-production pipeline with 3-tier testing
Hookenforce-container-first.shBlock bare-metal tflint/checkov/terraform on hostReproducible validation — same result on every machine
Hookenforce-docker-registry.shBlock non-compliant container registry referencesSLSA Level 2+ provenance — only signed enterprise images

Risk & Scalability

What happens without this pillar, and why ADLC scales from 1 person to enterprise

What if you skip?

McKinsey identifies seven capabilities needed for technology environments (Rewired S4, p.170): decoupled architecture, surgical cloud, engineering practices, developer productivity, production-grade solutions, security from the start, and MLOps. Without this pillar, infrastructure becomes the bottleneck that prevents all other pods from innovating.

Scalability

Docker-first enforcement and 3-tier IaC testing work identically on a laptop and in CI/CD. Config Aggregator discovers resources org-wide regardless of account count. The infrastructure tooling scales with the cloud footprint.

Industry Relevance

ANZ enterprise verticals where this pillar is most critical

FSI
Multi-account landing zones with SCPs for regulatory data residency
Energy
SCADA/OT network isolation via Terraform VPC modules
Telecom
Edge computing K3s clusters for 5G MEC workloads
Aviation
Air-gapped environments with supply-chain-verified container images

Continuous Improvement Flywheel

Each pillar feeds the next — creating a self-reinforcing cycle of capability building

Pillar 4 feeds Pillar 5
CloudOps & InfrastructureFinOps & Analytics

Infrastructure generates cost and usage data. FinOps transforms raw cloud spend into business intelligence.

Digital Products

Real products built and governed by this pillar

Explore Pillar 4 Components

Browse the full component catalog or read the documentation

AI agents build governed & Humans ship trusted.